← Back to Daily Briefing (#Trivy)

In March 2026, the TeamPCP cybercrime syndicate executed a targeted software supply-chain compromise against the Trivy security scanner, Checkmarx KICS (Infrastructure as Code scanner), and LiteLLM AI gateway. By injecting malicious code directly into these high-trust open-source repositories, the actors deployed automated credential-harvesting payloads. The campaign compromised over 500,000 credentials across more than 1,000 global organizations. Following an international investigation by the Australian Federal Police (AFP) and the FBI, suspects Louis Michael Gaebler and Ruben Ian Thomson were arrested in August 2026. This incident highlights the critical risk of "security tool weaponization" within DevSecOps and AI infrastructure pipelines.

  • Campaign Mechanics: Supply-Chain Injection

    • Attackers gained unauthorized access to trusted open-source repositories to inject malicious code into core components.
    • The payloads bypassed traditional perimeter defenses by riding on trusted update channels used by developers and security engineers.
    • The malicious code was specifically engineered for the automated exfiltration of secrets and credentials from host environments.
  • Targeted Ecosystems: DevSecOps and AI

    • Trivy: Compromised the container and VM security scanner to target vulnerability management pipelines.
    • Checkmarx KICS: Targeted Infrastructure as Code (IaC) scanning, allowing the attackers to potentially pivot into cloud configuration secrets.
    • LiteLLM: Exploited the AI gateway to harvest API keys and credentials from organizations integrating Large Language Models (LLMs).
  • Impact and Scale: Global Credential Theft

    • The operation resulted in the theft of over 500,000 unique credentials, creating massive long-term Identity and Access Management (IAM) risks.
    • More than 1,000 global organizations were affected, spanning various sectors including enterprise tech and critical infrastructure.
    • The scale of the breach underscores the exponential impact of compromising a single tool used by thousands of downstream users.
  • Attribution: Digital Forensics and OSINT

    • A joint operation between the AFP and FBI utilized a hybrid approach of digital forensics and Open Source Intelligence (OSINT).
    • Investigators successfully de-anonymized the suspects by correlating leaked passwords with metadata from decade-old legacy gaming profiles.
    • The arrests of Louis Michael Gaebler (23) and Ruben Ian Thomson (21) mark a significant victory in dismantling organized "syndicate-style" cybercrime.
  • Strategic Implications: Toolchain Fragility

    • The breach demonstrates the inherent fragility of the open-source supply chain, where "security" tools can be weaponized against the user.
    • Organizations are urged to implement rigorous Software Bill of Materials (SBOM) validation and repository integrity checks.
    • The incident highlights the need for "Zero Trust" applied to internal toolchains, ensuring security scanners operate with least-privilege access.

Related posts

  1. Cybersecurity News — Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations
  2. iTnews — Two Aussies alleged to be "principal participants" of TeamPCP hacking group
  3. feeds.feedburner.com — Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
  4. The Record by Recorded Future — Australia charges two men for TeamPCP supply-chain hacking spree
  5. helpnetsecurity.com — Two alleged TeamPCP hackers arrested over global supply chain attacks
  6. Security Affairs — Australian Police Charge Two Over TeamPCP Credential Theft
  7. cyberscoop.com — Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos
  8. esecurityplanet.com — Two Arrested in Australia Over TeamPCP Supply Chain Attacks
  9. Secarma
  10. Facebook

LINK COPIED TO CLIPBOARD